logo

Fake job recruiters hide malware in developer coding challenges

ID: a3d3bb21-f3bb-5ba4-8bc4-3139d40a3f56

STIX ID: report--a3d3bb21-f3bb-5ba4-8bc4-3139d40a3f56

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-02-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ReversingLabs identified a long-running fake recruiter campaign (Graphalgo) attributed to North Korea’s Lazarus group that targets JavaScript and Python developers by posting coding test job offers. The attacker publishes malicious packages to npm and PyPI which, when installed as dependencies, deploy a RAT capable of command execution, file exfiltration, and crypto wallet (MetaMask) checks; researchers found 192 malicious packages and observed delayed activation, token-protected C2, and multiple language variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.